<!DOCTYPE html>
<html lang="en">
<head>
	<meta charset="UTF-8">
	<meta http-equiv="X-UA-Compatible" content="IE=edge">
    <meta name="viewport" content="width=device-width, initial-scale=1">
	<title>日志记录 | Elasticsearch: 权威指南 | Elastic</title>
    <!-- Give IE8 a fighting chance -->
    <!--[if lt IE 9]>
    <script src="https://oss.maxcdn.com/html5shiv/3.7.2/html5shiv.min.js"></script>
    <script src="https://oss.maxcdn.com/respond/1.4.2/respond.min.js"></script>
    <![endif]-->
	<link rel="stylesheet" type="text/css" href="../static/styles.css" />
</head>
<body>
<div class="main-container">
    <section id="content">
        
        <div class="content-wrapper">
            <section id="guide" lang="zh_cn">
                <div class="container">
                    <div class="row">
                        <div class="col-xs-12 col-sm-8 col-md-8 guide-section">
                            <div style="color:gray; word-break: break-all; font-size:12px;">原文地址: <a href="https://www.elastic.co/guide/cn/elasticsearch/guide/current/logging.html" rel="nofollow">https://www.elastic.co/guide/cn/elasticsearch/guide/current/logging.html</a>, 版权归 www.elastic.co 所有<br/>
                            英文版地址: <a href="https://www.elastic.co/guide/en/elasticsearch/guide/current/logging.html" rel="nofollow">https://www.elastic.co/guide/en/elasticsearch/guide/current/logging.html</a>
                            </div>
                        <!-- start body -->
                  <div class="page_header">
<b>请注意:</b><br>本书基于 Elasticsearch 2.x 版本，有些内容可能已经过时。
</div>
<div id="content">
<div class="breadcrumbs">
<span class="breadcrumb-link"><a href="index.html">Elasticsearch: 权威指南</a></span>
»
<span class="breadcrumb-link"><a href="administration.html">管理、监控和部署</a></span>
»
<span class="breadcrumb-link"><a href="post_deploy.html">部署后</a></span>
»
<span class="breadcrumb-node">日志记录</span>
</div>
<div class="navheader">
<span class="prev">
<a href="_changing_settings_dynamically.html">« 动态变更设置</a>
</span>
<span class="next">
<a href="indexing-performance.html">索引性能技巧 »</a>
</span>
</div>
<div class="section">
<div class="titlepage"><div><div>
<h2 class="title">
<a id="logging"></a>日志记录<a class="edit_me edit_me_private" rel="nofollow" title="Editing on GitHub is available to Elastic" href="https://github.com/elasticsearch-cn/elasticsearch-definitive-guide/edit/cn/520_Post_Deployment/20_logging.asciidoc">edit</a>
</h2>
</div></div></div>
<p>Elasticsearch 会输出很多日志，都放在<code class="literal">ES_HOME/logs</code>目录下。

默认的日志记录等级是<code class="literal">INFO</code>。

它提供了适度的信息，但又设计得比较轻量，不至于让你的日志太过庞大。</p>

<p>当调试问题的时候，特别是节点发现相关的问题（因为这通常取决于复杂的网络配置），提高日志记录等级到 <code class="literal">DEBUG</code>是很有帮助的。</p>

<p>你<em>可以</em>修改 <code class="literal">logging.yml</code> 文件然后重启节点 —— 但是这样做即繁琐还会导致不必要的宕机时间。

相反，你可以用前面刚刚学过的<code class="literal">cluster-settings</code> API 更新日志记录等级。</p>

<p>要实现这个更新，选择你感兴趣的日志记录器，然后在前面补上 <code class="literal">logger.</code> 。对根日志记录器你可以用<code class="literal">logger._root</code>来表示。</p>

<p>让我们调高<code class="literal">发现(discovery)</code>模块的日志记录等级：</p>
<div class="pre_wrapper lang-js">
<pre class="programlisting prettyprint lang-js">PUT /_cluster/settings
{
    "transient" : {
        "logger.discovery" : "DEBUG"
    }
}</pre>
</div>

<p>设置生效，Elasticsearch 将开始为<code class="literal">discovery</code>模块输出<code class="literal">DEBUG</code>级别的日志。</p>

<div class="tip admon">
<div class="icon"></div>
<div class="admon_content">
<p>避免使用 <code class="literal">TRACE</code> 。这个级别非常的详细，详细到日志反而不再有用了。</p>
</div>
</div>
<div class="section">
<div class="titlepage"><div><div>
<h3 class="title">
<a id="slowlog"></a>慢日志 (slowlog)<a class="edit_me edit_me_private" rel="nofollow" title="Editing on GitHub is available to Elastic" href="https://github.com/elasticsearch-cn/elasticsearch-definitive-guide/edit/cn/520_Post_Deployment/20_logging.asciidoc">edit</a>
</h3>
</div></div></div>
<p>还有一个日志叫 <em>慢日志(slowlog)</em> 。

这个日志的目的是捕获那些超过指定时间阈值的查询和索引请求。

这个日志对于追踪由用户产生的特别慢的查询很有用。</p>

<p>默认情况，慢日志是不开启的。

要开启它，需要定义具体动作（query，fetch 还是 index）、期望的事件记录等级（ <code class="literal">WARN</code> 、 <code class="literal">DEBUG</code> 等）、时间阈值。</p>

<p>这是一个索引级别(index-level)的设置，也就是说可以独立应用到单个索引：</p>
<div class="pre_wrapper lang-js">
<pre class="programlisting prettyprint lang-js">PUT /my_index/_settings
{
    "index.search.slowlog.threshold.query.warn" : "10s", <a id="CO305-1"></a><i class="conum" data-value="1"></i>
    "index.search.slowlog.threshold.fetch.debug": "500ms", <a id="CO305-2"></a><i class="conum" data-value="2"></i>
    "index.indexing.slowlog.threshold.index.info": "5s" <a id="CO305-3"></a><i class="conum" data-value="3"></i>
}</pre>
</div>
<div class="calloutlist">
<table border="0" summary="Callout list">
<tr>
<td align="left" valign="top" width="5%">
<p><a href="#CO305-1"><i class="conum" data-value="1"></i></a></p>
</td>
<td align="left" valign="top">
<p>查询(query)时间超过 10 秒, 输出<code class="literal">WARN</code>级别的日志。</p>
</td>
</tr>
<tr>
<td align="left" valign="top" width="5%">
<p><a href="#CO305-2"><i class="conum" data-value="2"></i></a></p>
</td>
<td align="left" valign="top">
<p>获取(fetch)时间超过 500 毫秒，输出<code class="literal">DEBUG</code>级别的日志。</p>
</td>
</tr>
<tr>
<td align="left" valign="top" width="5%">
<p><a href="#CO305-3"><i class="conum" data-value="3"></i></a></p>
</td>
<td align="left" valign="top">
<p>索引<span style="color:#666;">写入</span>(indexing)时间超过 5 秒，输出<code class="literal">INFO</code>级别的日志。</p>
</td>
</tr>
</table>
</div>
<p>你也可以在<code class="literal">elasticsearch.yml</code>文件里定义这些阈值。

没有阈值设置的索引会自动继承在静态配置文件里配置的参数。</p>

<p>一旦阈值设置好了，你可以和其他日志记录器器一样切换日志记录等级：</p>

<div class="pre_wrapper lang-js">
<pre class="programlisting prettyprint lang-js">PUT /_cluster/settings
{
    "transient" : {
        "logger.index.search.slowlog" : "DEBUG", <a id="CO306-1"></a><i class="conum" data-value="1"></i>
        "logger.index.indexing.slowlog" : "WARN" <a id="CO306-2"></a><i class="conum" data-value="2"></i>
    }
}</pre>
</div>
<div class="calloutlist">
<table border="0" summary="Callout list">
<tr>
<td align="left" valign="top" width="5%">
<p><a href="#CO306-1"><i class="conum" data-value="1"></i></a></p>
</td>
<td align="left" valign="top">
<p>设置搜索(search)慢日志为<code class="literal">DEBUG</code>级别。</p>
</td>
</tr>
<tr>
<td align="left" valign="top" width="5%">
<p><a href="#CO306-2"><i class="conum" data-value="2"></i></a></p>
</td>
<td align="left" valign="top">
<p>设置索引<span style="color:#666;">写入</span>(indexing)慢日志为<code class="literal">WARN</code>级别。</p>
</td>
</tr>
</table>
</div>
</div>

</div>
<div class="navfooter">
<span class="prev">
<a href="_changing_settings_dynamically.html">« 动态变更设置</a>
</span>
<span class="next">
<a href="indexing-performance.html">索引性能技巧 »</a>
</span>
</div>
</div>

                  <!-- end body -->
                        </div>
                        <div class="col-xs-12 col-sm-4 col-md-4" id="right_col">
                        
                        </div>
                    </div>
                </div>
            </section>
        </div>
    </section>
</div>
<script src="../static/cn.js"></script>
</body>
</html>